The only role of 'ldap trust ids' now is to allow the primary group id to be
based entirely on the posix primary group, without being explictly set (using
the mapping). This is probably worth keeping. All other benifits are indeed
absent.